MFA shall be required to enroll devices to Azure AD
Last updated
Last updated
It is recommended to enforce MFA before a user can register or join their device to Azure AD. This ensures that compromised accounts cannot be used to add rogue devices to Azure Active Directory.
MFA shall be required to enroll devices to Azure AD.
This setting can be configured manually in all tenants via the Azure AD Portal. To enable this setting via Conditional Access, an Azure AD P1 license is required. Can be purchased standalone or part of the following bundles:
Microsoft 365 Business Premium
EMS+ E3 or EMS + E5
Microsoft 365 E3
Microsoft 365 E5
. Under Cloud Apps or actions, select User Actions from the dropdown
Checkmark the Register or Join Devices options
Under the grant controls, select Require Multifactor Authentication
None Currently
Users will get prompted with MFA when trying to register or join devices to Azure Active Directory. This could be through the out-of-box experience, users signing in via the company portal app, or users registering their devices through the account settings. If the user is brand new, has not set up MFA, and tries to join a device out-of-the box, a will need to be provided which will allow them to fulfill the MFA requirement.
For users trying to join Azure AD devices as part of the out-of-box experience or prior to getting to configure MFA, can be leveraged to fulfill the requirement